Auto Light Dark
Auto Light Dark

Create the OCI External KMS Private Endpoint

The Private Endpoint provides the private connection between OCI and the external KMS.

  1. In the OCI Console, go to Identity & Security → Private Endpoints.

  2. Click Create Private Endpoint.

Create Private Endpoint
Create Private Endpoint

Create Private Endpoint

  1. Enter the Private Endpoint name:

    <EKMS_PRIVATE_ENDPOINT_NAME>

  2. Select the VCN created previously.

  3. Select the required subnet.

  4. Enter the external KMS destination:

    <KMS_PRIVATE_IP/FQDN>

If the KMS has a private IP instead of a public IP, it will be necesary to configure a VPN / FastConnect. This configuration must be performed both in OCI and the KMS network.

  1. Enter port 443, or the port configured for the ESKM service.

Create Private Endpoint parameters
Create Private Endpoint parameters

Create Private Endpoint parameters

  1. Upload the CA bundle used to sign the ESKM’s service certificate:

<KMS_CA_BUNDLE>

  1. Click Create.

  1. Verify that the Private Endpoint is in the expected active state.